Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

AVAST našel rootkit:system modification

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Jeinee
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 06 pro 2011 17:16

AVAST našel rootkit:system modification

#1 Příspěvek od Jeinee »

Dobrý den,

velmi vás prosím o radu, už jsem vyzkoušela všechno možné.

Avast mi stále vyhledává jeden rootkit a to i přes jeho neustálé mazání a nenalezení viru při testu po restartu (při rychlém testu však rootkit znovu nalezen), AVG - Rootkitfree nic nenachází, ani SmitfraudFix nepomáhá...

hláška avastu:
C:WINDOWS/system32/drivers/sfloppy.sys
vysoká hrozba: Rootkit:system modification
SMAZAT
=> akce odložena do příštího restartu (nelze nějak změnit - aspoň mně :)

Už jsem počítač projela CCleanerem a výsledek z RootkitRevealeru tady:

HKLM\SECURITY\Policy\Secrets\SAC* 16.11.2006 16:47 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 16.11.2006 16:47 0 bytes Key name contains embedded nulls (*)
C:\Documents and Settings\Jana\Cookies\3CORHYY2.txt 6.12.2011 17:16 325 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Cookies\3IPKZL7U.txt 6.12.2011 17:05 283 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Jana\Cookies\40MM0YN2.txt 6.12.2011 17:11 101 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Jana\Cookies\6OU81CBE.txt 6.12.2011 17:16 103 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Cookies\8IC285CY.txt 6.12.2011 17:11 325 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Jana\Cookies\EWENH3GQ.txt 6.12.2011 17:05 243 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Jana\Cookies\IYTELU6I.txt 6.12.2011 17:17 243 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Cookies\MUAL061F.txt 6.12.2011 17:17 283 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Cookies\MVDNH3TY.txt 6.12.2011 17:17 79 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Cookies\PTLWO7F6.txt 6.12.2011 17:05 324 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Jana\Cookies\RFW2E6Y0.txt 6.12.2011 17:05 145 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Jana\Cookies\RZE8YK2I.txt 6.12.2011 17:17 145 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Cookies\SEV135H8.txt 6.12.2011 17:05 102 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Jana\Cookies\WNHIF6VQ.txt 6.12.2011 17:17 283 bytes Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Jana\Data aplikací\Microsoft\Office\Naposledy otev 3.12.2011 19:51 983 bytes Visible in Windows API, MFT, but not in directory index.
C:\Documents and Settings\Jana\Data aplikací\Microsoft\Office\Naposledy otev 6.12.2011 17:18 782 bytes Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Jana\Local Settings\Data aplikací\Microsoft\Internet Explorer\Recovery\Active\{DDA12A92-2025-11E1-805E-0013CE28AC6A}.dat 6.12.2011 17:18 5.50 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Jana\Local Settings\Temp\9.tmp 6.12.2011 17:18 16.00 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Jana\Local Settings\Temp\Do 6.12.2011 17:10 0 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temp\Do 1.11.2006 13:07 326.88 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temp\FAWEOB.exe 6.12.2011 17:11 374.88 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temp\Xl0000000.xls 6.12.2011 17:18 41.50 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Jana\Local Settings\Temp\~DF9EFC.tmp 6.12.2011 17:18 512 bytes Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\41[1].gif 6.12.2011 17:11 6.36 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\afr[1].htm 6.12.2011 17:05 1.02 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\background[1].gif 6.12.2011 17:17 56 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\bottom_bck[1].gif 6.12.2011 17:17 45 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\d0f52d50b08fd8fb62fcb5615ba0979e[1].swf 6.12.2011 17:15 7.40 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\favicon[3].ico 6.12.2011 17:17 1.37 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\fl[1].js 6.12.2011 17:15 6.55 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\forum_read_locked[1].gif 6.12.2011 17:16 673 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\forum_unread[1].gif 6.12.2011 17:16 663 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\hit[2].gif 6.12.2011 17:17 43 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\hit[3].gif 6.12.2011 17:17 43 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\hit[4].gif 6.12.2011 17:17 43 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\ico_f_jpg[1].gif 6.12.2011 17:17 119 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\ico_f_pdf[1].gif 6.12.2011 17:17 230 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\ico_fs_def[1].gif 6.12.2011 17:17 230 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\ico_fs_doc[1].gif 6.12.2011 17:17 241 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\ico_reply[1].gif 6.12.2011 17:17 67 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\index[2].htm 6.12.2011 17:16 30.89 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\james_virycz_vykricnik_zeleny[1].gif 6.12.2011 17:16 2.67 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\javascript[1] 6.12.2011 17:17 1.23 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\menu3[1].gif 6.12.2011 17:17 991 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\menud1[1].gif 6.12.2011 17:17 1.51 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\menud3[1].gif 6.12.2011 17:17 1.04 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\mod[1].gif 6.12.2011 17:11 436 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\PF[1].gif 6.12.2011 17:11 384 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\RANK_01[1].gif 6.12.2011 17:11 321 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\A66U942D\webmail-print[1].css 6.12.2011 17:17 448 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\10[1].gif 6.12.2011 17:11 6.63 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\1[1].png 6.12.2011 17:17 4.09 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\45[1].gif 6.12.2011 17:11 1018 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\54[1].gif 6.12.2011 17:11 5.06 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\54[2].gif 6.12.2011 17:11 5.06 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\5[1].gif 6.12.2011 17:17 253 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\6[1].gif 6.12.2011 17:11 1.89 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\78[1].gif 6.12.2011 17:11 4.46 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\962892_0[1].gif 6.12.2011 17:17 23.42 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\bhead[1].gif 6.12.2011 17:17 237 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\button_topic_reply[1].gif 6.12.2011 17:11 1.46 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\facebook_com[1].htm 6.12.2011 17:04 30.51 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\favicon[1].ico 6.12.2011 17:17 1.37 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\favicon[2].ico 6.12.2011 17:17 894 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\forum_read_subforum[1].gif 6.12.2011 17:16 705 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\hit[1].gif 6.12.2011 17:17 43 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\hit[2].gif 6.12.2011 17:17 43 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\hit[3].gif 6.12.2011 17:17 43 bytes Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\ico_f_def[1].gif 6.12.2011 17:17 135 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\ico_f_doc[1].gif 6.12.2011 17:17 137 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\ico_f_xls[1].gif 6.12.2011 17:17 134 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\james_virycz_vykricnik_cerveny[1].gif 6.12.2011 17:16 2.36 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\javascript[1] 6.12.2011 17:17 260 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\menu4[1].gif 6.12.2011 17:17 1.11 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\more_attachs[1].gif 6.12.2011 17:17 59 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\obalka_new[1].gif 6.12.2011 17:17 1023 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\GBO9CQ1R\slidingw[1].js 6.12.2011 17:17 12.06 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\11993[1].png 6.12.2011 17:11 11.60 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\172[1].gif 6.12.2011 17:11 7.20 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\1x1[1].gif 6.12.2011 17:15 807 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\26bf739e481a65479d55e48972df167a[1].gif 6.12.2011 17:15 12.44 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\419a38d799b1beca49e1b1f48268e375[1].gif 6.12.2011 17:11 54.73 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\958769_0[1].gif 6.12.2011 17:17 11.06 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\963352_0[1].jpg 6.12.2011 17:17 14.46 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\afr[1].htm 6.12.2011 17:11 1.10 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\cellpic2[1].jpg 6.12.2011 17:16 480 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\emptyScreen[1].htm 6.12.2011 17:17 117 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\favicon[2].ico 6.12.2011 17:17 1.37 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\forum_read[1].gif 6.12.2011 17:16 677 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\hit[2].gif 6.12.2011 17:17 43 bytes Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\ico_f_ppt[1].gif 6.12.2011 17:17 135 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\ico_forward[1].gif 6.12.2011 17:17 67 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\icon_smile[1].gif 6.12.2011 17:16 798 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\icon_topic_latest[1].gif 6.12.2011 17:16 135 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\logo-email[1].gif 6.12.2011 17:17 3.46 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\logo[1].gif 6.12.2011 17:17 2.56 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\mailboxStat[1] 6.12.2011 17:17 38 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\menu1[1].gif 6.12.2011 17:17 1.45 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\menu2h[1].gif 6.12.2011 17:17 1.21 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\neziskovky - excel[1].xlsx 6.12.2011 17:18 17.52 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\postak-ls[1].gif 6.12.2011 17:17 4.31 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\readMessageScreen[1].htm 6.12.2011 17:17 23.49 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\UBblue[1].png 6.12.2011 17:11 4.46 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\vizitka[1].gif 6.12.2011 17:17 107 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\H7NXFTX1\webmail[1].css 6.12.2011 17:17 42.55 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\2[1].gif 6.12.2011 17:11 2.13 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\45[1].gif 6.12.2011 17:11 1018 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\8[1].gif 6.12.2011 17:11 6.93 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\arrow_down[1].gif 6.12.2011 17:17 54 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\arrow_down_orange[1].gif 6.12.2011 17:17 54 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\arrow_up[1].gif 6.12.2011 17:17 55 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\donate[1].gif 6.12.2011 17:11 1.91 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\email-eset-transparent-white[1].png 6.12.2011 17:17 1.96 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\framesetScreen[1].htm 6.12.2011 17:17 1.54 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\hit[1].gif 6.12.2011 17:17 43 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\hit[2].gif 6.12.2011 17:17 43 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\hit[3].gif 6.12.2011 17:17 43 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\hit[4].gif 6.12.2011 17:17 43 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\hit[5].gif 6.12.2011 17:17 43 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\iconxquestion[1].gif 6.12.2011 17:11 1.17 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\james_virycz_vykricnik_modry[1].gif 6.12.2011 17:16 2.36 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\javascript[1] 6.12.2011 17:17 911 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\menu5[1].gif 6.12.2011 17:17 998 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\menu6[1].gif 6.12.2011 17:17 1.09 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\menu8[1].gif 6.12.2011 17:17 1.28 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\menud2[1].gif 6.12.2011 17:17 1.27 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\reklama_h[1].gif 6.12.2011 17:17 104 bytes Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\shop[1].gif 6.12.2011 17:11 1.77 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\user_info_pad0[1].gif 6.12.2011 17:17 4.21 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\webmail-write[1].js 6.12.2011 17:17 15.25 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\webmail[1].js 6.12.2011 17:17 40.23 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.IE5\MWZHVBRY\whosonline[1].gif 6.12.2011 17:16 5.16 KB Hidden from Windows API.
C:\Documents and Settings\Jana\Local Settings\Temporary Internet Files\Content.MSO 6.12.2011 17:18 0 bytes Visible in directory index, but not Windows API or MFT.
C:\System Volume Information\_restore{653AE5DD-6F55-4CEE-9326-D2ACBB9B5572}\RP1056\A0153303.LNK 3.12.2011 19:51 983 bytes Visible in directory index, but not Windows API or MFT.
C:\System Volume Information\_restore{653AE5DD-6F55-4CEE-9326-D2ACBB9B5572}\RP1056\A0153304.LNK 4.12.2011 16:47 662 bytes Visible in directory index, but not Windows API or MFT.






Ještě dodatek: stejný problém mám i na svém druhém počítači (totožný rootkit)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: AVAST našel rootkit:system modification

#2 Příspěvek od vyosek »

Zdravim a pekny vecer preji :)

:arrow: Jedna se o falesnou detekci Avastu

:arrow: Aktualizujte rucne databazi Avastu, mela by problem vyresit
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jeinee
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 06 pro 2011 17:16

Re: AVAST našel rootkit:system modification

#3 Příspěvek od Jeinee »

Děkuji moc, netušila jsem, že náprava bude tak jednoduchá, ale alespoň jsem si "vyčistila" počítač. Ještě jednou díky :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: AVAST našel rootkit:system modification

#4 Příspěvek od vyosek »

Nemate zac, rado se stalo...

Pokud chcete, dejte jeste log z RSIT a mrknem po pripadnych dalsich drobnostech...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jeinee
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 06 pro 2011 17:16

Re: AVAST našel rootkit:system modification

#5 Příspěvek od Jeinee »

Doufám, že to pro mě nebude nepříjemné překvapení, log:




Logfile of random's system information tool 1.09 (written by random/random)
Run by Jana at 2011-12-06 19:33:54
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 7 GB (24%) free of 27 GB
Total RAM: 502 MB (24% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:34:11, on 6.12.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\acer\epm\epm-dm.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\TO2SSM\McciTrayApp.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Jana\Plocha\RSIT.exe
C:\Program Files\trend micro\Jana.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\1007\toolbaru.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [TO2SSM_McciTrayApp] C:\Program Files\TO2SSM\McciTrayApp.exe
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.slunecnice.cz
O15 - Trusted Zone: *.stahuj.cz
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {50E43D86-A74D-11D0-98CE-004005249458} (AnimatedGif Control) - https://www.mojebanka.cz/jars/confwiz/MVSGif.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: winmm.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

--
End of file - 9192 bytes

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Jana\Data aplikací\Mozilla\Firefox\Profiles\v3hiafyo.default

prefs.js - "browser.startup.homepage" - "http://start.icq.com/"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... 2.0.0.1&q="

"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@macromedia.com/FlashPlayer10]
"Description"=Adobe Flash Player 10.0
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\\extensions\
{800b5000-a755-47e1-992b-48a1c1357f07}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\\components\
browser.xpt
jar50.dll
jsconsole-clhandler.js
jsd3250.dll
nsBrowserContentHandler.js
nsBrowserGlue.js
nsCloseAllWindows.js
nsDictionary.js
nsExtensionManager.js
nsHelperAppDlg.js
nsIQTScriptablePlugin.xpt
nsPostUpdateWin.js
nsProxyAutoConfig.js
nsSetDefaultBrowser.js
nsSidebar.js
nsUpdateService.js
nsXmlRpcClient.js
xpinstal.dll

C:\Program Files\Mozilla Firefox\\plugins\
npdeploytk.dll
npnul32.dll
NPOFFICE.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class

C:\Program Files\Mozilla Firefox\\searchplugins\
centrum-cz.png
centrum-cz.src
google.gif
google.src
jyxo-cz.gif
jyxo-cz.src
mall-cz.png
mall-cz.src
seznam-cz.gif
seznam-cz.src
slunecnice-cz.gif
slunecnice-cz.src

C:\Documents and Settings\Jana\Data aplikací\Mozilla\Firefox\Profiles\v3hiafyo.default\extensions\
{20a82645-c095-46ed-80e3-08825760534b}
{800b5000-a755-47e1-992b-48a1c1357f07}
{EEE6C361-6118-11DC-9C72-001320C79847}

C:\Documents and Settings\Jana\Data aplikací\Mozilla\Firefox\Profiles\v3hiafyo.default\searchplugins\
icqplugin.gif
icqplugin.src
icqplugin.xml
sweetim.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - C:\PROGRA~1\ICQTOO~1\1007\toolbaru.dll [2006-12-25 701952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-04-23 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-04-23 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2011-08-17 1055808]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2005-06-08 94208]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2005-06-08 77824]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2005-06-08 114688]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
"AzMixerSel"=C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [2005-06-11 53248]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-08-09 14743552]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"EPM-DM"=c:\acer\epm\epm-dm.exe [2005-08-11 200704]
"ePowerManagement"=C:\Acer\ePM\ePM.exe [2005-03-15 2893824]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2004-10-08 98394]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2004-10-08 688218]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2003-10-31 32768]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-09-01 282624]
""= []
"IntelWireless"=C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [2004-10-15 385024]
"EOUApp"=C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe [2004-10-15 356352]
"tsnpstd3"=C:\WINDOWS\tsnpstd3.exe [2005-12-20 94208]
"snpstd3"=C:\WINDOWS\vsnpstd3.exe [2005-09-05 339968]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472]
"OpwareSE4"=C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe [2007-02-04 79400]
"TO2SSM_McciTrayApp"=C:\Program Files\TO2SSM\McciTrayApp.exe [2009-01-16 1473536]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-11-28 3744552]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-09-07 37296]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

C:\Documents and Settings\Jana\Nabídka Start\Programy\Po spuštění
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="winmm.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2005-06-08 131072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll [2004-10-15 110592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2006-09-20 441136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQLite\ICQLite.exe"="C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. The whole world can talk for free."
"C:\Program Files\ICQ7.6\ICQ.exe"="C:\Program Files\ICQ7.6\ICQ.exe:*:Enabled:ICQ7.6"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.6\ICQ.exe"="C:\Program Files\ICQ7.6\ICQ.exe:*:Enabled:ICQ7.6"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=serwvdrv.dll
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll
"wave2"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"midi9"=C:\DOCUME~1\Jana\LOCALS~1\Temp\idpcys.bak 2nEJPKEMFO
"wave4"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv

======List of files/folders created in the last 1 month======

2011-12-06 19:33:58 ----D---- C:\Program Files\trend micro
2011-12-06 19:33:53 ----D---- C:\rsit
2011-12-06 17:29:06 ----A---- C:\WINDOWS\system32\RootkitReveal.txt
2011-12-06 16:13:12 ----D---- C:\Program Files\CCleaner
2011-12-06 15:43:30 ----RASHOT---- C:\WINDOWS\winstart.bat
2011-12-06 15:41:32 ----D---- C:\Documents and Settings\Jana\Data aplikací\Uniblue
2011-12-06 15:40:30 ----HDC---- C:\Documents and Settings\All Users\Data aplikací\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
2011-12-06 15:40:22 ----D---- C:\Program Files\Uniblue
2011-12-06 13:54:07 ----ASH---- C:\hiberfil.sys
2011-12-06 13:47:54 ----A---- C:\WINDOWS\system32\tmp.txt
2011-12-06 13:47:42 ----A---- C:\rapport.txt
2011-12-06 13:47:34 ----A---- C:\WINDOWS\system32\WS2Fix.exe
2011-12-06 13:47:34 ----A---- C:\WINDOWS\system32\VCCLSID.exe
2011-12-06 13:47:34 ----A---- C:\WINDOWS\system32\VACFix.exe
2011-12-06 13:47:34 ----A---- C:\WINDOWS\system32\swxcacls.exe
2011-12-06 13:47:34 ----A---- C:\WINDOWS\system32\swsc.exe
2011-12-06 13:47:34 ----A---- C:\WINDOWS\system32\swreg.exe
2011-12-06 13:47:34 ----A---- C:\WINDOWS\system32\SrchSTS.exe
2011-12-06 13:47:34 ----A---- C:\WINDOWS\system32\Process.exe
2011-12-06 13:47:34 ----A---- C:\WINDOWS\system32\o4Patch.exe
2011-12-06 13:47:34 ----A---- C:\WINDOWS\system32\IEDFix.exe
2011-12-06 13:47:34 ----A---- C:\WINDOWS\system32\IEDFix.C.exe
2011-12-06 13:47:34 ----A---- C:\WINDOWS\system32\dumphive.exe
2011-12-06 13:47:34 ----A---- C:\WINDOWS\system32\Agent.OMZ.Fix.exe
2011-12-06 13:47:34 ----A---- C:\WINDOWS\system32\404Fix.exe
2011-11-11 21:38:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2641690$
2011-11-09 23:36:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893-v2$

======List of files/folders modified in the last 1 month======

2011-12-06 19:33:58 ----RD---- C:\Program Files
2011-12-06 19:22:25 ----D---- C:\WINDOWS\system32\drivers
2011-12-06 19:08:30 ----D---- C:\WINDOWS\Temp
2011-12-06 17:29:35 ----D---- C:\WINDOWS\system32
2011-12-06 16:58:27 ----D---- C:\WINDOWS\system32\Lang
2011-12-06 16:53:44 ----D---- C:\WINDOWS
2011-12-06 16:51:43 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-12-06 16:38:43 ----D---- C:\WINDOWS\Debug
2011-12-06 16:38:39 ----D---- C:\WINDOWS\Minidump
2011-12-06 15:46:35 ----SD---- C:\WINDOWS\Tasks
2011-12-06 15:42:40 ----D---- C:\WINDOWS\Prefetch
2011-12-06 13:57:02 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-12-06 11:51:55 ----D---- C:\Program Files\TO2SAM
2011-12-06 00:36:54 ----D---- C:\WINDOWS\system32\CatRoot2
2011-11-28 19:01:23 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-11-11 21:38:29 ----HD---- C:\WINDOWS\inf
2011-11-11 21:38:24 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-11-11 15:58:55 ----HD---- C:\WINDOWS\$hf_mig$
2011-11-09 23:31:19 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2008-04-10 44944]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-11-28 30808]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-11-28 34392]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-11-28 435032]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-11-28 314456]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-11-28 52952]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.1.6.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2006-11-20 17119]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-11-28 20568]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-11-28 111320]
R2 EpmPsd;Acer EPM Power Scheme Driver; \??\C:\WINDOWS\system32\drivers\epm-psd.sys []
R2 EpmShd;Acer EPM System Hardware Driver; \??\C:\WINDOWS\system32\drivers\epm-shd.sys []
R2 MaVctrl;MaVctrl; C:\WINDOWS\system32\DRIVERS\MaVc2K.sys [2004-08-23 11089]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R2 osaio;osaio; \??\C:\WINDOWS\system32\drivers\osaio.sys []
R2 osanbm;osanbm; \??\C:\WINDOWS\system32\drivers\osanbm.sys []
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2004-10-15 11354]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-06-30 1034752]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2005-06-30 200704]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-06-08 1050140]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-08-09 3855360]
R3 IWCA;Intel Wireless Connection Agent Miniport for Win XP; C:\WINDOWS\system32\DRIVERS\iwca.sys [2004-08-12 234496]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-03-04 74496]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2004-10-08 185824]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 w29n51;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows XP; C:\WINDOWS\system32\DRIVERS\w29n51.sys [2004-10-29 3222784]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-06-30 716416]
R4 AVG Anti-Rootkit;AVG Anti-Rootkit; C:\WINDOWS\System32\DRIVERS\avgarkt.sys []
R4 AvgArCln;Avg Anti-Rootkit Clean Driver; C:\WINDOWS\System32\DRIVERS\AvgArCln.sys []
S0 Partizan;Partizan; C:\WINDOWS\system32\drivers\Partizan.sys []
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 MaRdPnp;MaRdPnp; C:\WINDOWS\system32\DRIVERS\MaRdP2K.sys [2005-08-18 49867]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS []
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS []
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 P730C;P730C; C:\WINDOWS\system32\DRIVERS\P730C.sys [2004-09-16 25300]
S3 P730M;P730M; C:\WINDOWS\system32\DRIVERS\P730M.sys [2004-09-16 25300]
S3 P730U;P730U; C:\WINDOWS\system32\DRIVERS\P730U.sys [2005-05-25 49365]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SNPSTD3;USB PC Camera (SNPSTD3); C:\WINDOWS\system32\DRIVERS\snpstd3.sys [2005-12-08 8718848]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 anbmService;Notebook Manager Service; C:\Acer\eManager\anbmServ.exe [2005-06-06 1273344]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-11-28 44768]
R2 EvtEng;EvtEng; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2004-10-15 86016]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2011-08-17 247872]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-04-23 152984]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-02-17 73728]
R2 McciCMService;McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [2007-10-15 303104]
R2 OwnershipProtocol;OwnershipProtocol; C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe [2004-10-15 98304]
R2 RegSrvc;RegSrvc; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2004-10-15 139264]
R2 S24EventMonitor;Spectrum24 Event Monitor; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2004-10-15 360521]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: AVAST našel rootkit:system modification

#6 Příspěvek od vyosek »

:arrow: Odinstalujte ICQ Toolbar - je to uzasne zpomalovadlo :?:

:arrow: Stahnete OTM (viz muj podpis)
  • Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
  • Kód: Vybrat vše

    :services
    ICQ Service
    
    :reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{855F3B16-6D32-4FE6-8A56-BBB695989046}"=-
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "RemoteControl"=-
    "NeroFilterCheck"=-
    "QuickTime Task"=-
    ""=-
    "Adobe Reader Speed Launcher"=-
    "Adobe ARM"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{855F3B16-6D32-4fe6-8A56-BBB695989046}"=-
    
    :files
    C:\Documents and Settings\Jana\Data aplikací\Mozilla\Firefox\Profiles\v3hiafyo.default\searchplugins\icqplugin*.*
    C:\Documents and Settings\Jana\Data aplikací\Mozilla\Firefox\Profiles\v3hiafyo.default\searchplugins\sweetim.xml
    C:\Program Files\ICQ6Toolbar
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
  • Kliknete na cervene tlacitko MoveIt!
  • Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jeinee
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 06 pro 2011 17:16

Re: AVAST našel rootkit:system modification

#7 Příspěvek od Jeinee »

All processes killed
========== SERVICES/DRIVERS ==========
Service ICQ Service stopped successfully!
Service ICQ Service deleted successfully!
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RemoteControl deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MSMSGS deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
========== FILES ==========
C:\Documents and Settings\Jana\Data aplikací\Mozilla\Firefox\Profiles\v3hiafyo.default\searchplugins\icqplugin.gif moved successfully.
C:\Documents and Settings\Jana\Data aplikací\Mozilla\Firefox\Profiles\v3hiafyo.default\searchplugins\icqplugin.src moved successfully.
C:\Documents and Settings\Jana\Data aplikací\Mozilla\Firefox\Profiles\v3hiafyo.default\searchplugins\icqplugin.xml moved successfully.
C:\Documents and Settings\Jana\Data aplikací\Mozilla\Firefox\Profiles\v3hiafyo.default\searchplugins\sweetim.xml moved successfully.
C:\Program Files\ICQ6Toolbar folder moved successfully.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
C:\WINDOWS\system32\SET69.tmp moved successfully.
C:\WINDOWS\002017_.tmp moved successfully.
C:\WINDOWS\005201_.tmp moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET7.tmp moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Jana
->Temp folder emptied: 1694435 bytes
->Temporary Internet Files folder emptied: 22977999 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 46893 bytes
->Flash cache emptied: 1926876 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33237 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 2504 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 970136 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 156533406 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 6657499 bytes

Total Files Cleaned = 182,00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User

User: Jana
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0,00 mb


OTM by OldTimer - Version 3.1.19.0 log created on 12062011_201425

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: AVAST našel rootkit:system modification

#8 Příspěvek od vyosek »

Jak se chova nas pacient :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jeinee
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 06 pro 2011 17:16

Re: AVAST našel rootkit:system modification

#9 Příspěvek od Jeinee »

Vše se jeví OK, díky.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: AVAST našel rootkit:system modification

#10 Příspěvek od vyosek »

:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět